cbcvebase.
CVE-2023-53213
published 2025-09-15

CVE-2023-53213: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Fix a slab-out-of-bounds…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.15%
4.9th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() Fix a slab-out-of-bounds read that occurs in kmemdup() called from brcmf_get_assoc_ies(). The bug could occur when assoc_info->req_len, data from a URB provided by a USB device, is bigger than the size of buffer which is defined as WL_EXTRA_BUF_MAX. Add the size check for req_len/resp_len of assoc_info. Found by a modified version of syzkaller. [ 46.592467][ T7] ================================================================== [ 46.594687][ T7] BUG: KASAN: slab-out-of-bounds in kmemdup+0x3e/0x50 [ 46.596572][ T7] Read of size 3014656 at addr ffff888019442000 by task kworker/0:1/7 [ 46.598575][ T7] [ 46.599157][ T7] CPU: 0 PID: 7 Comm: kworker/0:1 Tainted: G O 5.14.0+ #145 [ 46.601333][ T7] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.1-0-ga5cab58e9a3f-prebuilt.qemu.org 04/01/2014 [ 46.604360][ T7] Workqueue: events brcmf_fweh_event_worker [ 46.605943][ T7] Call Trace: [ 46.606584][ T7] dump_stack_lvl+0x8e/0xd1 [ 46.607446][ T7] print_address_description.constprop.0.cold+0x93/0x334 [ 46.608610][ T7] ? kmemdup+0x3e/0x50 [ 46.609341][ T7] kasan_report.cold+0x79/0xd5 [ 46.610151][ T7] ? kmemdup+0x3e/0x50 [ 46.610796][ T7] kasan_check_range+0x14e/0x1b0 [ 46.611691][ T7] memcpy+0x20/0x60 [ 46.612323][ T7] kmemdup+0x3e/0x50 [ 46.612987][ T7] brcmf_get_assoc_ies+0x967/0xf60 [ 46.613904][ T7] ? brcmf_notify_vif_event+0x3d0/0x3d0 [ 46.614831][ T7] ? lock_chain_count+0x20/0x20 [ 46.615683][ T7] ? mark_lock.part.0+0xfc/0x2770 [ 46.616552][ T7] ? lock_chain_count+0x20/0x20 [ 46.617409][ T7] ? mark_lock.part.0+0xfc/0x2770 [ 46.618244][ T7] ? lock_chain_count+0x20/0x20 [ 46.619024][ T7] brcmf_bss_connect_done.constprop.0+0x241/0x2e0 [ 46.620019][ T7] ? brcmf_parse_configure_security.isra.0+0x2a0/0x2a0 [ 46.620818][ T7] ? __lock_acquire+0x181f/0x5790 [ 46.621462][ T7] brcmf_notify_connect_status+0x448/0x1950 [ 46.622134][

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.27-1 (bookworm)linux 6.1.27-1 (bookworm)
linuxlinux
linuxlinux>= cf2b448852abd47cee21007b8313fbf962bf3c9a < ac5305e5d227b9af3aae25fa83380d3ff0225b73ac5305e5d227b9af3aae25fa83380d3ff0225b73
linuxlinux>= cf2b448852abd47cee21007b8313fbf962bf3c9a < 39f9bd880abac6068bedb24a4e16e7bd26bf92da39f9bd880abac6068bedb24a4e16e7bd26bf92da
linuxlinux>= cf2b448852abd47cee21007b8313fbf962bf3c9a < 425eea395f1f5ae349fb55f7fe51d833a5324bfe425eea395f1f5ae349fb55f7fe51d833a5324bfe
linuxlinux>= cf2b448852abd47cee21007b8313fbf962bf3c9a < 549825602e3e6449927ca1ea1a08fd89868439df549825602e3e6449927ca1ea1a08fd89868439df
linuxlinux>= cf2b448852abd47cee21007b8313fbf962bf3c9a < 936a23293bbb3332bdf4cdb9c1496e80cb0bc2c8936a23293bbb3332bdf4cdb9c1496e80cb0bc2c8
linuxlinux>= cf2b448852abd47cee21007b8313fbf962bf3c9a < e29661611e6e71027159a3140e818ef3b99f32dde29661611e6e71027159a3140e818ef3b99f32dd
linuxlinux>= cf2b448852abd47cee21007b8313fbf962bf3c9a < 228186629ea970cc78b7d7d5f593f2d32fddf9f6228186629ea970cc78b7d7d5f593f2d32fddf9f6
linuxlinux>= cf2b448852abd47cee21007b8313fbf962bf3c9a < 21bee3e649d87f78fe8aef6ae02edd3d6f310fd021bee3e649d87f78fe8aef6ae02edd3d6f310fd0
linuxlinux>= cf2b448852abd47cee21007b8313fbf962bf3c9a < 0da40e018fd034d87c9460123fa7f897b69fdee70da40e018fd034d87c9460123fa7f897b69fdee7
linuxlinux_kernel< 4.14.3154.14.315
linuxlinux_kernel>= 0 < 5.10.191-15.10.191-1
linuxlinux_kernel>= 0 < 6.1.27-16.1.27-1
linuxlinux_kernel>= 0 < 6.1.27-16.1.27-1
linuxlinux_kernel>= 0 < 6.1.27-16.1.27-1
linuxlinux_kernel>= 4.15 < 4.19.2834.19.283
linuxlinux_kernel>= 4.20 < 5.4.2435.4.243
linuxlinux_kernel>= 5.11 < 5.15.1105.15.110
linuxlinux_kernel>= 5.16 < 6.1.276.1.27
linuxlinux_kernel>= 5.5 < 5.10.1805.10.180
linuxlinux_kernel>= 6.2 < 6.2.146.2.14
linuxlinux_kernel>= 6.3 < 6.3.16.3.1

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.